AWS PrivateLink
AWS PrivateLink is the technology behind interface VPC endpoints: elastic network interfaces with private IPs in your subnets that connect to an AWS service, a partner service or an application that another VPC exposes behind a Network Load Balancer. Traffic stays in the AWS network and needs no Internet gateway or NAT gateway.
Gateway endpoints are a different, free mechanism, only for S3 and DynamoDB.
Interface endpoints are charged per hour per Availability Zone and per GB processed. See VPC endpoints with Terraform.